A new Internet Explorer 6 vulnerability has been documented by Secunia and so far no exploits have surfaced. Still folks should always be careful with sites they visit and avoid all URL links in spam email.
Internet Explorer 6 "object" Tag Memory Corruption Code Execution
http://secunia.com/advisories/19762/
QUOTE: The vulnerability is caused due to an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site. Successful exploitation allows execution of arbitrary code. The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.